Everything previously under www/src now are under www/ Moved style.CSS under www/ressources, to allow blocking http requests to www/lib completly Moved <head> and <header> generation under lib/PHP/output/sections.php to reduce redundancy within files. Also implemented a system to allow them to generate relatif paht for href to ressources depending on their deepness within www/ hierarchy.
22 lines
624 B
PHP
22 lines
624 B
PHP
<?php
|
|
|
|
require_once "update.php";
|
|
|
|
// Used in secure context. Ask if you need to use this.
|
|
|
|
function generate_CSRF_token(): string {
|
|
// Dunno wether random_bytes() is secure.
|
|
$_SESSION['CSRF'] = bin2hex(random_bytes(32));
|
|
return $_SESSION['CSRF'];
|
|
}
|
|
|
|
function CSRF_field(): string {
|
|
return '<input type="hidden" name="CSRF_token" value="'.htmlspecialchars(generate_CSRF_token(), ENT_QUOTES).'">';
|
|
}
|
|
|
|
function CSRF_verify(): bool {
|
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|
return isset($_POST['CSRF_token'], $_SESSION['CSRF']) && hash_equals($_SESSION['CSRF'], $_POST['CSRF_token']);
|
|
}
|
|
return false;
|
|
}
|